Insights

Trust Is Becoming the Real AI Battleground for Banks

Banks have spent centuries refining a single business model. They borrow trust, transform it into financial activity, and spend every day trying not to lose it. That is what makes a recent reflection from Bank of Ireland more interesting than it first appears. On its surface, it reads like another executive essay about artificial intelligence, full of familiar references to fraud detection, customer service, compliance monitoring, and operational efficiency. Those examples are almost expected now. Every large financial institution has a similar catalogue of use cases.

Reality, Not Snapshots: Rethinking Third-Party Risk

Every risk discipline carries a habit that outlives its usefulness. In third-party risk management, that habit is the self-attested questionnaire. It is the artifact the whole practice is organized around. A relationship begins, a security questionnaire goes out, the vendor returns a few hundred answers, an analyst reviews them, and the file is closed until next year's cycle. The ritual is so established that it is easy to forget it was built for a smaller, slower, more stable world than the one we operate in now

Legislation As Code: The Future Architecture of Governance

Modern governance runs on digital systems, but law is still written as if humans are the only interpreters, creating a growing gap between policy intent and machine execution. Every time statute is translated into software, invisible interpretation occurs, turning ambiguity into operational reality and shifting policymaking into technical layers outside democratic visibility. Legislation-as-code closes that gap by pairing human-readable law with executable logic that can be tested, audited, and simulated before it governs real people, treating policy as infrastructure rather than static text. Early efforts such as New Zealand’s Better Rules initiative show this transition is already underway, and the real challenge is ensuring computational governance remains transparent enough to preserve public trust while modernizing how societies enforce rules.

Why Ethical Culture Is Becoming Measurable

The Department of Justice's Evaluation of Corporate Compliance Programs contains a question that would have sounded almost eccentric a generation ago. Prosecutors are instructed to ask whether a company has measured its culture. Not whether it published a code of conduct polished to a corporate sheen, nor whether employees dutifully completed another round of ethics training before the deadline, but whether the organization possesses evidence, actual evidence, about the beliefs and behaviors that determine what happens after the policy manual closes and the meeting adjourns.

Is Risk Management a 2nd Line Function in the Updated Three Lines Model?

The Institute of Internal Auditors' updated Three Lines Model has reignited a longstanding debate over where risk management belongs within an organization's governance structure. In this commentary, governance and risk expert Norman Marks examines whether the revised definition of the second line finally reflects the reality of modern risk management, or simply broadens the concept so far that it loses much of its practical value. He argues that while the new language is an improvement over earlier versions, it raises fundamental questions about the purpose of the model and whether it still meaningfully distinguishes assurance providers from decision-support functions.

The Next Competitive Advantage in GRC Is No Longer Software

For much of the past twenty-five years, the GRC technology market rewarded providers for building broader platforms. New modules became competitive advantages. More configurable workflows became competitive advantages. Larger control libraries, deeper reporting, additional dashboards, more sophisticated risk quantification, and expanded third-party capabilities, with every release cycle promising another collection of features designed to distinguish one platform from another. Buyers responded in kind, and procurement teams assembled exhaustive requirements, while consultants developed detailed evaluation methodologies. Analysts compared products capability by capability until selection often resembled an exercise in accounting rather than strategy.

How AI Is Changing Internal Audit Before It Changes AI Governance

The first time artificial intelligence changes an audit function, it probably won't be because an auditor is reviewing an AI governance framework. It will be because someone quietly asks a large language model to summarize a hundred-page policy, compare two years of control testing, identify unusual journal entries, or draft the first version of an audit report.